logo

Navigating PCI DSS 4.0: Insights from Industry Experts on Client-Side Security

ID: 932c1031-45d0-5df2-950b-94a4f4facf77

STIX ID: report--932c1031-45d0-5df2-950b-94a4f4facf77

Feed Name: Security Boulevard

Date Published: 2024-08-26

Date Updated: 2026-04-22

Author: Scott Fiesel

...
...

This blog summarizes a QSA roundtable on PCI DSS v4.0’s expanded client-side security requirements (notably 6.4.3 and 11.6.1), highlighting the rising risk of eSkimming/Magecart and formjacking, and the need to inventory, authorize, and verify the integrity of scripts on payment pages. Panelists emphasize that even sites using redirects/iframes are now in scope, note the operational challenges of maintaining script inventories, and describe the practical limits of CSP/SRI in dynamic environments. The key recommendation is to adopt automated, real-time client-side monitoring and control solutions to meet the April 2025 compliance timeline and reduce exposure to client-side data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.